DEC 28, 2005 1:00am ET

Related Links

The State of Cloud Standards
February 10, 2012
CIO Stepping Stones to Success
February 10, 2012
Oracle to Buy Taleo
February 9, 2012

Web Seminars

6 Key Things to Fast Track your Mobility Strategy
February 23, 2012
Why Getting Started in MDM Doesn't Have to Be Difficult
February 29, 2012
Dashboards: How's Business? Ask your Data!
March 15, 2012

Poll: Lack of Protection Leaves Merchants Open to Data Security Breaches

Print
Reprints
Email

A poll released by Protegrity Corporation, a provider of data security management solutions, found that Payment Card Industry Data Security Standard (PCI) compliance is severely lagging at merchants of all levels despite a growing Internet fraud rate.

During a recent Protegrity webcast on "Accelerating PCI Compliance: Real World Experiences and Strategies" featuring Intuit, respondents were asked what is the status of their PCI compliance efforts, 45 percent said they are in the very early stages of the compliance process, while 19 percent said they have not passed their initial assessment. Only 3 percent said they have passed an assessment.

According to the 7th Annual CyberSource Fraud survey, dollar losses from e-commerce fraud continued to mount for merchants. In 2005, total losses to online fraud will exceed $2.8 billion, up from $2.6 billion in 2004, with large and midsize merchants finding the issue most difficult to address.

To meet the PCI standards merchants of all sizes are required to:

1. Install and maintain a firewall configuration to protect data.

2. Do not use vendor-supplied defaults for system passwords and other security parameters.

3. Protect Stored Data.

4. Encrypt transmission of cardholder data and sensitive information across public networks.

5. Use and regularly update anti-virus software.

6. Develop and maintain secure systems and applications.

7. Restrict access to data by business need-to-know.

8. Assign a unique ID to each person with computer access.

9. Restrict physical access to cardholder data.

10. Track and monitor all access to network resources and cardholder data.

11. Regularly test security systems and processes.

12. Maintain a policy that addresses information security.

Merchants and providers who do not comply may receive fines and/or face restrictions - or in severe cases, be prohibited from accepting credit card(s).

In a poll follow up question, respondents were asked how does PCI compliance compare with other regulations in terms of 2006 compliance projects? 24 percent said PCI is one of their most important projects, 25 percent said PCI is about as important as SOX in importance, 25 percent said all compliance projects are of equal importance, 15 percent said PCI ranks behind both federal and state privacy and disclosure laws in importance, and 8 percent said PCI is just barely on their radar screen.

This piece is brought to you by the Information Management editorial staff.

Filed under:
GRC

Advertisement

Comments (0)

Be the first to comment on this post using the section below.

Add Your Comments:
You must be registered to post a comment.
Not Registered?
You must be registered to post a comment. Click here to register.
Already registered? Log in here
Please note you must now log in with your email address and password.
Twitter
Facebook
LinkedIn
Login  |  My Account  |  White Papers  |  Web Seminars  |  Events |  Newsletters |  eBooks
FOLLOW US
Please note you must now log in with your email address and password.